Privacy Policy - Warwick Punjabi Society
Effective Date: 22nd September 2026
1. Who We Are
This website, warwickpsoc.co.uk, is run by Warwick Punjabi Society ("we", "us", "our"), an independent student society.
For the purposes of the UK GDPR and the Data Protection Act 2018, Warwick Punjabi Society is the data controller of the personal information collected through this website. That means we decide how and why your information is used, and we are your first point of contact for anything relating to your data.
Our website, membership system, and ticketing system are provided by the Platform, operated by Deevan Parmar and Jayden Patel (the "Platform Provider"). The Platform Provider hosts and processes your information on our behalf and on our instructions as our data processor.
Working on our behalf, the Platform Provider may use your information to: run and administer the website; provide technical support and fix problems, including looking at and correcting records when we ask them to; build, test, fix, maintain and improve the platform - while doing which their staff may incidentally see your information; investigate and prevent fraud, abuse and security incidents; and meet their own legal obligations. Anyone with that access, including any contractor they may use, is bound by confidentiality obligations.
What the Platform Provider will not do: it does not sell your information, does not use it for its own marketing, and does not use it in a form that identifies you to build products or services unrelated to running this website.
Separately, the Platform Provider acts as a data controller in its own right for a short, closed list of platform-level purposes: the accounts of society administrators and its own billing records; platform-wide security and preventing fraud and abuse; meeting its legal obligations and dealing with legal claims; and statistics and insights in aggregated or fully anonymised form, used to run and improve the platform. Fully anonymised information can no longer be traced back to you and is not personal data. That list is exhaustive - the Platform Provider does not act as a controller of your information for anything else.
2. What Information We Collect
- Account and membership information: your name, email address, membership type and status (including which membership tiers you previously held and when they expired), and your university/student ID number. There are no other account fields - we don't ask for anything beyond what's listed here.
- Tickets and events: records of tickets you buy or free places you claim, which events you attend, and how many tickets or places you took. Our event and ticket forms don't have any free-text fields - we don't currently ask for dietary requirements, accessibility needs, or anything similar when you buy a ticket.
- Payments: payments are processed by Stripe. Your card details go directly to Stripe and are never stored on this website. We and the Platform Provider only see a payment reference (such as a Stripe customer or session ID) - not your card details, and not even the amount of any individual transaction, which Stripe holds, not us. Stripe processes your payment information as an independent controller under its own privacy policy: https://stripe.com/privacy
- Terms acceptance: when you sign up, we record which version of these terms you accepted, when, and the IP address your device used at that moment - captured once, at signup, as evidence that you accepted, not as an ongoing record of your activity.
- Signing in: we use an essential sign-in cookie to keep you logged in while you use the site (more on this in section 6). We do not track which pages you visit, and we don't use analytics or advertising cookies.
3. How We Use Your Information
- To create and manage your account and membership
- To sell and manage event tickets, and to run events
- To send you essential emails about your account, purchases and membership (for example, confirming your account, sending you a one-time sign-in code, or reminding you before your membership expires)
These emails are delivered by the Platform Provider on our behalf and will come from an address ending in deevanjayden.com, the Platform's own domain; the email itself will always name the Society. Emails about this Site from any other domain should be treated with suspicion.
- To keep the website secure and prevent fraud and abuse
- To keep membership and financial records for our own administration
If we ever introduce optional emails about society news or events beyond the essential emails above, we will only send them with your consent, and you will be able to opt out at any time.
4. Legal Bases
We rely on: contract (to provide your membership and tickets); consent (if we ever introduce optional communications, or any non-essential cookies - none exist today, but if that changes you'll be able to withdraw consent at any time); legitimate interests (website security, service improvement, and administration of the society); and legal obligation (record-keeping required by law).
5. Who We Share Your Information With
We do not sell your personal information. We share it only with:
- The Platform Provider, which hosts and operates this website on our behalf;
- The Platform Provider's own service providers: Supabase (database and authentication), Resend (delivery of account and membership emails, such as sign-up confirmation, one-time sign-in codes, and membership expiry reminders), Vercel (website hosting), and Cloudflare (bot-prevention on the sign-up page only, via its Turnstile product - see section 6);
- Stripe, for payment processing (as an independent controller);
- Authorities or regulators, where we are legally required to do so.
Links to other websites. Some events on this Site are ticketed by external providers. In those cases the "Get tickets" button simply takes you to the third party's own website; this Site passes none of your information to them. Anything you enter there, including any purchase, is collected by that third party under its own privacy policy, not this one. Where we (the Society) run an event through such a provider, the provider may share attendee information with us directly, for example so we know who is coming, under our own arrangement with them; that exchange happens outside this website and the Platform Provider is not involved in it. The same goes for any other external link on this Site: once you leave, this policy no longer applies.
6. Cookies and Analytics
We use essential cookies only - specifically, the sign-in cookie that keeps you logged in while you use the site. It's strictly necessary for the site to work, so we don't need to ask your consent to use it, which is why there's no cookie banner here. We don't use any analytics, advertising, or tracking cookies, and we don't store anything else in your browser.
The one other thing worth mentioning is our sign-up page, which uses Cloudflare Turnstile to check that you're a real person rather than a bot - a more modern, privacy-friendly alternative to the old "select all the traffic lights" puzzles. Turnstile does not set any cookies (we've directly tested and confirmed this): it briefly communicates with Cloudflare using signals like your IP address and browser environment to assess whether you're likely human, and nothing is stored in your browser as a result.
7. How Long We Keep Your Information
We keep your information only as long as necessary: membership records for the duration of your membership and a reasonable period afterwards; records of which membership tiers you previously held and when they expired, for up to 2 years after that membership expired, so the Society can keep year-to-year membership lists and see who may wish to rejoin, after which they are deleted or anonymised; ticket and payment records for up to 6 years, where needed for financial and audit purposes; attendance records for free events (where no payment was involved) for up to 2 years after the event, so the Society can see attendance history and plan future events, after which they are deleted or anonymised; and marketing preferences until you withdraw consent or your account is deleted. Some transaction records cannot be deleted earlier because they are required for financial integrity and audit - in that case, your name, email, and other identifying details are irreversibly removed from the record (so it can no longer be linked to you), but the record itself (for example, that a ticket was bought for a particular event) is kept until the 6-year period ends.
If we (the Society) ever stop using the Platform, your information may be kept by the Platform Provider in a dormant, unused state for up to 12 months at our direction, in case we resume using it, before being deleted or anonymised on the basis described above.
8. International Transfers
Your information may be processed outside the UK/EEA by the service providers listed above. Where this happens, appropriate safeguards are used (such as UK adequacy regulations, the UK International Data Transfer Addendum, or Standard Contractual Clauses).
9. Security
Your information is protected using encryption in transit, access controls that separate each society's data, and restricted administrative access. Signing in uses single-use, time-limited sign-in codes sent to your email address; we do not store passwords at all. No system is completely secure, but we and the Platform Provider take reasonable steps to protect your information.
Because signing in works through your email, keeping your email account secure is essential: anyone with access to your inbox could access your account here.
10. Your Rights
Under the UK GDPR you have the right to: access your data; have it corrected or deleted; restrict or object to processing; data portability; and withdraw consent at any time. Where a record must be kept for the financial/audit reasons described in section 7, we fulfil an erasure request by irreversibly anonymising the personal data within it rather than deleting the record outright - the practical effect for you is the same: the record can no longer be linked to you.
To exercise any of these rights, contact us (the Society) at warwickpsoc@gmail.com. Because we are the data controller, requests must come to us - if you contact the Platform Provider directly, they will refer you back to us. Where a request involves records we cannot change ourselves, we will instruct the Platform Provider to action it.
You also have the right to complain to the Information Commissioner's Office (ICO): https://ico.org.uk
11. Age Requirement
This website is intended for users aged 16 or over. We do not knowingly collect data from anyone under 16.
12. Changes to This Policy
We may update this policy from time to time. The latest version will always be published on this page with its effective date.
13. Contact
- Data controller (contact first): Warwick Punjabi Society - warwickpsoc@gmail.com
- Platform Provider (technical issues only): the Platform - jaydenpatel16@outlook.com